Multiple vulnerabilities in SLUB: Event Registration extension for TYPO3

Published: 2019-10-15 | Updated: 2019-10-15
Severity High
Patch available YES
Number of vulnerabilities 3
CVE ID CVE-2019-16700
CVE-2019-11358
CVE-2015-2531
CWE ID CWE-434
CWE-400
CWE-79
Exploitation vector Network
Public exploit Public exploit code for vulnerability #2 is available.
Vulnerable software SLUB: Event Registration Subscribe
Vendor TYPO3

Security Advisory

1) Arbitrary file upload

Severity: High

CVSSv3: 8.5 [CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C] [PCI]

CVE-ID: CVE-2019-16700

CWE-ID: CWE-434 - Unrestricted Upload of File with Dangerous Type

Description

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to the affected software allows to upload arbitrary files to the webserver. A remote attacker can upload and execute arbitrary file on the server (For versions 1.2.2 and below) or cause a denial of service (DoS) condition, since the webspace can be filled up with arbitrary files (versions later than 1.2.2).

Mitigation

Install updates from the vendor's website.

Vulnerable software versions

SLUB: Event Registration: 1.0.7, 1.0.8, 1.0.10, 1.0.11, 1.0.15, 1.0.17, 1.0.19, 1.0.26, 1.1.0, 1.1.1, 1.1.5, 1.1.8, 1.2.0, 1.2.2, 1.4.0, 1.4.1, 1.4.2, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.4.0, 2.4.1, 2.4.2, 2.4.3, 3.0.0, 3.0.1, 3.0.2

CPE External links

https://typo3.org/security/advisory/typo3-ext-sa-2019-017/

Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Prototype pollution

Severity: Low

CVSSv3: 4.8 [CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C] [PCI]

CVE-ID: CVE-2019-11358

CWE-ID: CWE-400 - Uncontrolled Resource Consumption ('Resource Exhaustion')

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to prototype pollution. A remote attacker can trick the extend function can into modifying the prototype of Object when the attacker controls part of the structure passed to this function. This can let an attacker add or modify an existing property that will then exist on all objects and perform a denial of service (DoS) attack.

Mitigation

Install updates from the vendor's website.

Vulnerable software versions

SLUB: Event Registration: 1.0.7, 1.0.8, 1.0.10, 1.0.11, 1.0.15, 1.0.17, 1.0.19, 1.0.26, 1.1.0, 1.1.1, 1.1.5, 1.1.8, 1.2.0, 1.2.2, 1.4.0, 1.4.1, 1.4.2, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.4.0, 2.4.1, 2.4.2, 2.4.3, 3.0.0, 3.0.1, 3.0.2

CPE External links

https://typo3.org/security/advisory/typo3-ext-sa-2019-017/

Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.

3) Cross-site scripting

Severity: Low

CVSSv3: 5.3 [CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C] [PCI]

CVE-ID: CVE-2015-2531

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Description

The vulnerability allows a remote attacker to perform XSS attacks.

The vulnerability is caused by an input validation error in the jQuery engine in Microsoft Lync Server 2013 and Skype for Business Server 2015. A remote attacker can trick the victim to follow a specially specially crafted link and execute arbitrary HTML and script code in victim's browser in security context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.

Mitigation

Install updates from the vendor's website.

Vulnerable software versions

SLUB: Event Registration: 1.0.7, 1.0.8, 1.0.10, 1.0.11, 1.0.15, 1.0.17, 1.0.19, 1.0.26, 1.1.0, 1.1.1, 1.1.5, 1.1.8, 1.2.0, 1.2.2, 1.4.0, 1.4.1, 1.4.2, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.4.0, 2.4.1, 2.4.2, 2.4.3, 3.0.0, 3.0.1, 3.0.2

CPE External links

https://typo3.org/security/advisory/typo3-ext-sa-2019-017/

Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.